VDB
Sign up
MEDIUM5.3

GHSA-9986-w5h5-vw59

Directory traversal in Mort Bay Jetty

Quick fix

GHSA-9986-w5h5-vw59 — org.mortbay.jetty:jetty: upgrade to the fixed version with the command below.

# pom.xml: bump <version>6.1.17</version> for org.mortbay.jetty:jetty

Details

Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.mortbay.jetty:jetty
Introduced in: 0Fixed in: 6.1.17
Fix# pom.xml: bump <version>6.1.17</version> for org.mortbay.jetty:jetty
Maven/org.mortbay.jetty:jetty
Introduced in: 7.0.0.M0Fixed in: 7.0.0.M2
Fix# pom.xml: bump <version>7.0.0.M2</version> for org.mortbay.jetty:jetty

References